Privacy Policy
Last updated: May 12, 2026
1. Introduction
Welcome to RedGifs AI. This Privacy Policy is designed to help you understand how ERS Interactive ("RedGifs AI," "we," "our," or "us") collects, uses, and safeguards the information you provide to us through our website, mobile application, and other digital services (collectively, the "Services").
By accessing or using our Services, you agree to the practices described in this Privacy Policy. If you do not agree with this Policy, please do not access or use our Services.
ERS Interactive is the data controller responsible for your personal data. We are committed to protecting your privacy and complying with applicable data protection laws.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide directly to us when you use our Services. This may include:
- Account information (e.g., username, email address)
- Profile information
- Content you create, share, or post on our Services
- Communications you send to us
- Survey responses
2.2 Information We Collect Automatically
When you access or use our Services, we may automatically collect certain information, including:
- Device information (e.g., device type, operating system)
- Log data (e.g., IP address, access times)
- Usage data (e.g., features used, content viewed)
- Location data (with your permission)
2.3 Information from Other Sources
We may receive information about you from other sources, including:
- Other users of our Services
- Social media platforms, if you connect your account to our Services
- Third-party services that you use to log into our Services
2.4 Legal Basis for Processing (for EU Users)
For users in the European Union, we process your personal data based on one or more of the following legal grounds:
- Your consent
- Performance of a contract with you
- Compliance with a legal obligation
- Our legitimate interests, provided they do not override your fundamental rights and freedoms
3. How We Use the Information We Collect
We use the information we collect for various purposes, including:
- Providing, maintaining, and improving our Services
- Personalizing your experience
- Communicating with you about our Services
- Analyzing usage patterns and trends
- Detecting and preventing fraud and abuse
- Complying with legal obligations
We may also use aggregated or de-identified data for any purpose, which is not subject to restrictions under this Privacy Policy.
For EU users, we process your data for these purposes based on the legal grounds outlined in Section 2.4.
4. When We Disclose the Information We Collect
We may share your information in the following circumstances:
4.1 With Affiliates
We may share information with our affiliated companies for purposes consistent with this Privacy Policy.
4.2 With Service Providers
We may share information with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf.
4.3 For Legal Reasons
We may share information if we believe it's necessary to comply with applicable laws, regulations, legal processes, or governmental requests.
4.4 In Connection with Business Transfers
If we're involved in a merger, acquisition, financing, or sale of business assets, we may transfer your information as part of that transaction.
4.5 With Your Consent
We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent.
4.6 User Content and Public Features
Some features of our Services may allow you to share information publicly. Any information you submit through such features will be publicly available.
4.7 International Data Transfers
Your information may be transferred to, and processed in, countries other than the country you live in. These countries may have data protection laws different from the laws of your country. We implement appropriate safeguards to protect your information when transferred internationally.
5. Cookie Policy
5.1 What are Cookies?
Cookies are small data files stored on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to the owners of the site.
5.2 Types of Cookies We Use
We use the following types of cookies:
- Essential Cookies — necessary for the website to function properly.
- Functional Cookies — remember your preferences and enhance your experience.
- Analytics Cookies — help us understand how visitors interact with our website.
- Advertising Cookies — used to deliver relevant ads and track ad campaign performance.
5.3 How We Use Cookies
We use cookies to:
- Keep you signed in
- Remember your preferences
- Understand how you use our Services
- Improve our Services
- Deliver relevant advertising
5.4 Third-Party Cookies
Some cookies may be placed by third parties when you use our Services. These third parties may collect your information for their own purposes.
5.5 Managing Cookies
Most web browsers allow you to control cookies through their settings. However, if you limit the ability of websites to set cookies, you may worsen your overall user experience.
5.6 Do Not Track
Some browsers have a "Do Not Track" feature that lets you tell websites that you do not want to have your online activities tracked. We currently do not respond to "Do Not Track" signals.
6. Online Analytics and Advertising
6.1 Analytics Services
We use analytics services to help us understand how users engage with our Services. These services may use cookies and similar technologies to collect information about your use of the Services and other websites.
6.2 Advertising
We may work with third-party advertising companies to serve ads when you visit or use our Services. These companies may use information about your visits to our website and other websites to provide relevant advertisements about goods and services that may interest you.
6.3 Your Choices
You can opt out of certain advertising features through your device settings, ad network preferences, or our Services settings. For more information about opting out of interest-based advertising, visit www.aboutads.info/choices or www.youronlinechoices.eu.
7. User Choices and Rights
7.1 Account Information
You can update, correct, or delete your account information at any time from your account settings. If you need assistance, please contact us at legal@thepeach.ai
7.2 Communication Preferences
You can opt out of receiving promotional communications from us by following the instructions in those communications. If you opt out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.
7.3 Cookie Preferences
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may impact the functionality of our Services.
7.4 Data Subject Rights
Depending on your location, you may have certain rights regarding your personal information, including:
- The right to access your personal information
- The right to rectify inaccurate personal information
- The right to request the deletion of your personal information
- The right to restrict the processing of your personal information
- The right to data portability. You can self-serve a machine-readable export of your account data at any time from your account settings (subject to a once-per-day limit), or by contacting us at the address in section 7.6.
- The right to object to the processing of your personal information
You can adjust which categories of email you receive in your settings, unsubscribe from all non-essential email, or delete your account — at which point we also cancel any email already queued to you.
7.5 Additional Rights for EU Users
If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR), including:
- The right to withdraw consent at any time
- The right to lodge a complaint with a supervisory authority
7.6 Exercising Your Rights
To exercise any of these rights, please contact us at legal@thepeach.ai We will respond to your request in accordance with applicable data protection laws.
8. Children's Privacy
8.1 Age Restrictions
Our Services are intended for adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18.
8.2 Handling of Underage Users' Data
If we learn that we have collected personal information from a person under 18, we will take steps to delete that information as quickly as possible. If you believe that we might have any information from or about a person under 18, please contact us at legal@thepeach.ai
9. Security Measures
We take reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. However, no internet or electronic communications service is ever completely secure or error-free.
9.1 Data Protection Measures
We implement various security measures to maintain the safety of your personal information when you use our Services, including:
- Encryption of sensitive information
- Regular security audits
- Access controls to limit employee access to personal information
- Secure data storage practices
9.2 User Responsibilities
While we strive to protect your personal information, the security of your data also depends on you. We urge you to take steps to keep your personal information safe, such as choosing a strong password and keeping it private, as well as logging out of your account after using shared computers.
9.3 Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by applicable laws.
10. Data Retention
10.1 How long we keep your data
When you delete your account through the in-app "Delete account" control or by emailing legal@thepeach.ai, we run a two-step erasure flow:
- Immediately: we scrub the personal-identifier columns on your user record (email, handle, display name, bio, avatar), revoke every active session, cancel and delete your upstream payments customer record, retire every companion you own, hard-delete your direct-message conversations together with the messages in them, erase your email-category preferences, and cancel any transactional email already queued or scheduled to you that has not yet been sent.
- After a 30-day grace window: we hard-delete your authentication credentials, your draft companion creation work, and orphaned media binaries. The grace window exists so a deletion requested by mistake — or by an account takeover — can be reversed by re-authenticating; once it elapses, the deletion is irreversible.
10.2 What survives the deletion
Some content is retained in anonymized form because removing it would distort other users' experience:
- Public-room messages you sent are deleted with your account; the rest of the conversation thread continues without your lines.
- Comments and reactions you made on public posts authored by other users remain attached to the post but are reattributed to a generic "deleted user" placeholder. Other users' ability to read the post is preserved; your identity is not.
- Audit and security event logs are retained for the period required to investigate fraud, abuse, and security incidents, and to satisfy our legal and regulatory recordkeeping duties. These logs reference the system-generated user identifier and a record of which categories of transactional email we sent you (by date and email type — never the message contents). Personal identifiers are scrubbed at deletion; the category-level send record is retained for the legal and regulatory recordkeeping period.
10.3 No deactivation-without-delete
We do not offer a separate "deactivate" or "pause" option that retains your data without active use. The only ways your data leaves the active system are: (a) you delete your account, or (b) we delete it for cause (terms violation, court order, regulatory direction). In either case the same two-step erasure flow runs.
10.4 Backups
Encrypted database backups are retained for operational disaster recovery on a rolling window not exceeding 35 days. Restored copies of your data, if any, are re-subjected to the deletion you previously requested when the backup is rehydrated; we do not re-create deleted accounts from backup absent a documented incident response.
11. International Data Transfers
11.1 Where your data is processed
We currently operate the Services from a single Google Cloud Platform region: us-central1 (Iowa, United States). Application servers, primary database, and object storage all reside in that region. We do not currently replicate to additional regions.
11.2 Transfers from the EEA / UK
If you access the Services from the European Economic Area, the United Kingdom, or Switzerland, your personal information is transferred to and processed in the United States. We rely on the data subject's informed consent (Article 49(1)(a) GDPR) at registration as the lawful basis for that transfer; the "I confirm I am 18 or older" checkpoint discloses the cross-border processing context.
11.3 Future regions
When we begin processing personal information in additional regions or under additional transfer mechanisms (for example, the EU-US Data Privacy Framework or Standard Contractual Clauses), we will update this section before traffic begins flowing and provide a meaningful notice through the "Notification of Changes" mechanism in §13.
11.4 Further information
For questions about the specific safeguards in place for your transfer, contact us at legal@thepeach.ai
12. Sub-Processors
We rely on the third-party providers listed below to operate the Services. Each row identifies the data we send, the purpose, and our deletion contract — what happens to the data at the provider when you delete your account or we cease using the provider.
12.1 Provider list
- Google Cloud Platform (Cloud SQL for PostgreSQL, Google Cloud Storage, Google Kubernetes Engine, Cloud Build) — hosts the application database, uploaded and generated media binaries, and the application runtime. Region: us-central1. Deletion contract: account deletion removes your rows from the database and clears references to your media; orphaned objects in Cloud Storage are reaped by a daily lifecycle sweep, with the storage bucket's own 35-day lifecycle rule as the backstop. This 35-day bucket-lifecycle window is separate from the 30-day account-deletion grace window described in §10.
- Stripe, Inc. — processes subscription payments and stores the payment-method tokens linked to your account. Data sent: account identifier, billing email, subscription status, payment method tokens. Deletion contract: account deletion calls Stripe's subscription cancel API for every active subscription and the customer-delete API for the upstream record; Stripe retains the resulting transaction history per its own legal-and-tax-compliance retention schedule, which we cannot override.
- Anthropic, PBC (Claude API) — processes conversational prompts and character generation requests when configured as the language-model backend. Data sent: prompt text, recent conversation context, generation parameters. Deletion contract: per Anthropic's API terms, prompts are not used to train models; ephemeral inference logs are retained on Anthropic's side per their published policy. We do not send your account email or other direct identifiers.
- Self-hosted vLLM cluster (when configured) — alternative language-model backend operated under our own control in us-central1. Data sent: same as above. Deletion contract: the cluster does not persist prompts beyond the request lifetime.
- Image generation providers (Seedream, NanoBanana, Veo) — generate companion avatars and other imagery. Data sent: text prompts derived from your character descriptions; no account identifiers. Deletion contract: prompt-derived generated assets we receive back are stored in our Google Cloud Storage bucket and are subject to the deletion flow above. Provider-side retention of the prompt text itself follows each vendor's policy and we do not control it.
- Email transactional relay (operated in-cluster by us) — sends verification codes, password recovery, and account-state notifications. Data sent: destination email address, message body, delivery status. Deletion contract: account deletion removes your email from the customer-app database, so no further outbound mail is queued; bounce-and-suppression metadata may persist on the relay until cleared by an operator-initiated purge. The address held in suppression metadata is the same address you provided; no other personal information is retained there.
- BytePlus (media asset library, ap-southeast-1) — an offshore media-asset processor in Southeast Asia that stores generated companion avatar and media assets. Data sent: companion-derived asset references and generated media asset-group identifiers only; we do not send your account email, handle, or other direct identifiers. International transfer: assets are stored in the ap-southeast-1 region. Deletion contract: account deletion deletes the associated asset groups on BytePlus (idempotent on a remote not-found), driven by the same anonymization flow above and a bounded retry job.
12.2 Adding a sub-processor
We will update this list before sending personal information to any new sub-processor. Material additions are announced through the §13 notification mechanism.
12.3 Links to other sites
The Services may contain links to third-party websites that are not sub-processors and do not receive your personal information from us. We are not responsible for those sites' privacy practices and encourage you to review their policies before providing them with personal information.
13. Changes to the Privacy Policy and Cookie Policy
13.1 Policy Updates
We may update this Privacy Policy and Cookie Policy from time to time. The updated version will be indicated by an updated "Last Updated" date and the updated version will be effective as soon as it is accessible.
13.2 Notification of Changes
If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.
13.3 Continued Use of Services
Your continued use of our Services after the effective date of any change to the Privacy Policy will constitute your acceptance of the amended Privacy Policy. If you do not agree to the revised policy, please discontinue using our Services.
14. Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
- ERS Interactive
- Email: legal@thepeach.ai
We operate virtually and do not maintain a physical office address.
For users in the European Union:
- Contact details of EU representative: legal@thepeach.ai
- Contact details of Data Protection Officer: legal@thepeach.ai
15. Regional Privacy Disclosures
15.1 California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). These rights include:
- The right to know what personal information we collect about you and how we use and disclose it
- The right to request deletion of your personal information
- The right to opt-out of the sale of your personal information
- The right to non-discrimination for exercising your CCPA rights
To exercise your CCPA rights, please contact us at legal@thepeach.ai
15.2 European Economic Area (EEA) and United Kingdom Residents
If you are located in the EEA or UK, you have certain rights under the GDPR and UK GDPR, respectively. These include:
- The right to be informed about our processing of your personal data
- The right to access and receive a copy of your personal data
- The right to rectification of any inaccurate personal data
- The right to erasure of your personal data in certain circumstances
- The right to restrict processing of your personal data
- The right to data portability
- The right to object to processing based on legitimate interests
- Rights related to automated decision-making and profiling
To exercise these rights, please contact us at legal@thepeach.ai
15.3 Nevada Residents
Nevada residents have the right to opt out of the sale of certain "covered information" collected by operators of websites or online services. We currently do not sell covered information, as "sell" is defined by Nevada law, and we don't have plans to do so in the future.
15.4 GDPR Compliance
For users in the European Union, we comply with the GDPR. This includes:
- Processing personal data lawfully, fairly, and transparently
- Collecting personal data only for specified, explicit, and legitimate purposes
- Ensuring personal data is adequate, relevant, and limited to what is necessary
- Keeping personal data accurate and up to date
- Storing personal data only as long as necessary
- Processing personal data in a manner that ensures appropriate security
If you have any questions about our GDPR compliance, please contact us at legal@thepeach.ai
Appendix R — Adult Surface (redgifs.thepeach.ai) Privacy Addendum
This appendix supplements the global Privacy Policy above for users accessing the Services through the adult (NSFW) surface operated by ERS Interactive. In the event of a conflict between the global policy and this appendix, the appendix controls for users on this surface. The effective date of this appendix matches the global policy date: May 12, 2026.
R.1 Age-attestation gate disclosure. Access to the Services on this surface requires that you affirmatively confirm at registration that you are at least 18 years old (or the age of legal majority in your jurisdiction, if higher). This is a self-attestation: we record that you affirmed it and the timestamp of that affirmation. We do NOT collect a government-issued identification document, a selfie or any biometric or liveness signal, or your date of birth, and we do NOT route any identity materials to a third-party identity-verification provider. Should a stronger age-verification mechanism be required by the law of your jurisdiction, ERS Interactive will disclose it here and in the sub-processor list of the global policy before it takes effect.
R.2 Adult-content data processing. Prompts, conversations, and generated imagery on this surface may contain sexually explicit material. Such content is treated as special-category personal data where local law so requires (notably: GDPR Article 9 categories where they apply). We process this data on the basis of your explicit consent given at registration; you may withdraw consent at any time by deleting your account, which triggers the two-step erasure flow described in the global policy §10. We do not share explicit conversation content with third parties for advertising or analytics purposes; sub-processor disclosures in the global policy §12 govern all other sharing.
R.3 18 U.S.C. § 2257 records custodian. To the extent records-keeping obligations under 18 U.S.C. § 2257 and 28 C.F.R. Part 75 apply to imagery generated, hosted, or made available through the Services on this surface, ERS Interactive is the designated records custodian. Custodian contact: legal@thepeach.ai. The Services do not depict real human performers; AI-generated imagery is produced from text prompts and provider models, and we maintain records sufficient to demonstrate the non-human, AI-generated provenance of material produced through the Services. A formal 2257 statement, including the physical custodian address required by the regulation, will be posted in connection with any production launch and supersedes this placeholder.
R.4 State-specific addenda. Certain US states have enacted age-verification statutes applicable to adult-content websites (including but not limited to Texas, Louisiana, Utah, Virginia, Mississippi, Arkansas, Montana, North Carolina, and Tennessee). The age gate currently operated on this surface is the self-attestation described in R.1. Where a statute applicable to your jurisdiction requires a stronger age-verification mechanism than self-attestation, ERS Interactive will either implement a compliant mechanism — disclosed here before it takes effect — or withhold the Services from that jurisdiction rather than operate in violation of the statute. This appendix is a pre-launch placeholder pending review by external counsel. Contact legal@thepeach.ai with questions specific to your state of residence.